Remove Pingback-Trackback Comments Security & Risk Analysis

wordpress.org/plugins/remove-pingback-trackback-comments

One step process to remove pingbacks and trackbacks and leave only real user opinions in your posts comments.

100 active installs v1.0 PHP + WP 3.3.2+ Updated Aug 31, 2015
commentcommentspingbackpingbackstrackback
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Remove Pingback-Trackback Comments Safe to Use in 2026?

Generally Safe

Score 85/100

Remove Pingback-Trackback Comments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The 'remove-pingback-trackback-comments' plugin v1.0 exhibits a strong security posture based on the provided static analysis and vulnerability history. The attack surface is minimal with no identified AJAX handlers, REST API routes, shortcodes, or cron events, and crucially, none of these are unprotected. This suggests a well-designed plugin with limited entry points for potential attackers. The code signals also point to generally good practices, with no dangerous functions or file operations identified. The presence of a nonce check and capability check further bolster its security. However, a significant concern arises from the SQL queries: all six queries are executed without prepared statements. This leaves the plugin vulnerable to SQL injection attacks, a critical flaw. While the plugin has no recorded vulnerability history, the lack of prepared statements in SQL queries represents a clear and present danger.

Key Concerns

  • All SQL queries lack prepared statements
  • 25% of output is not properly escaped
Vulnerabilities
None known

Remove Pingback-Trackback Comments Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Remove Pingback-Trackback Comments Code Analysis

Dangerous Functions
0
Raw SQL Queries
6
0 prepared
Unescaped Output
3
1 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared6 total queries

Output Escaping

25% escaped4 total outputs
Attack Surface

Remove Pingback-Trackback Comments Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actioninitremove-pingback-trackback-comments.php:36
actionadmin_menuremove-pingback-trackback-comments.php:88
Maintenance & Trust

Remove Pingback-Trackback Comments Maintenance & Trust

Maintenance Signals

WordPress version tested4.3.34
Last updatedAug 31, 2015
PHP min version
Downloads5K

Community Trust

Rating100/100
Number of ratings3
Active installs100
Developer Profile

Remove Pingback-Trackback Comments Developer Profile

Pau Iglesias

8 plugins · 620 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Remove Pingback-Trackback Comments

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/remove-pingback-trackback-comments/css/style.css/wp-content/plugins/remove-pingback-trackback-comments/js/script.js
Script Paths
/wp-content/plugins/remove-pingback-trackback-comments/js/script.js
Version Parameters
remove-pingback-trackback-comments/css/style.css?ver=remove-pingback-trackback-comments/js/script.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Remove Pingback-Trackback Comments